HKTL_USURF
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Hacking Tool
Destructiveness: No
Encrypted:
In the wild: Yes
TECHNICAL DETAILS
Varies
PE
No
02 Nov 2008
Other System Modifications
This hacking tool modifies the following registry key(s)/entry(ies) as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\ CurrentVersion\Internet Settings
ProxyEnable = "1"
(Note: The default value data of the said registry entry is "0".)
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\ CurrentVersion\Internet Settings\
Zones\3
1C00 = "hex:00,00,00,00,"
(Note: The default value data of the said registry entry is dword:00010000.)
It also creates the following registry entry(ies) as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\International\CpMRU
HKEY_CURRENT_USER\Software\Microsoft\
Windows\ CurrentVersion\Internet Settings
~vyjbuiv = "dword:0000049f"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\ CurrentVersion\Internet Settings
ProxyOverride = "local"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\ CurrentVersion\Internet Settings
ProxyServer = "127.0.0.1:9666"
SOLUTION
9.200
Step 1
Scan your computer with your Trend Micro product to delete files detected as HKTL_USURF. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Step 2
Restore this modified registry value
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
RESTOREDid this description help? Tell us how we did.